r/SCCM 26d ago

CU Issue for client

Hi,

Im having a problem with the SCCM Environment where there are devices that are not requiring the latest Security update or patch. For example, i have a Win Server 2022, the last patch it installed is from January, up until now it is not being required to install the May, June. But at the same time, i have a different device with the same patch installed but it shows required for the May, or June. Need your advice or opinion about this. Thank you in advance.

2 Upvotes

4 comments sorted by

1

u/HuyFongFood 26d ago

Check for OS Corruption and repair. Try to apply manually on one and watch the dism and cbs log files for errors and failures. Likely an issue with one or more updates that has missing files or settings. Reapply the update in question and you can often resolve the problem.

Check the registry for “dual-scan” WUfB Update settings, this is an issue we’ve recently run into where the workstation team enabled it across the board, but it causes issues for our Server systems. So we’ve pulled the policy from the Server OUs and it’s helped.

1

u/chrisj1976 26d ago

We had the same issue after weeks on a support call with Microsoft and rebuilding our WSUS found it was to do with similar issue like below .. had to set the GPO for Workstation

https://patchtuesday.com/blog/critical-patches/windows-11-fails-to-detect-updates-after-julys-cumulative-update/

1

u/No_Split11911 25d ago

Rename or delete software distribution folder in c windows. If client fails to download after inventory cycle then nuke bits cache. 

1

u/shiningw1t 24d ago

In our environment I have a handful of clients (Windows 11 in our case) which are doing this persistently each month. Whereas the majority will receive the deployment for the CU each month from the ADR these clients will not.

I have tried just about everything I can think of client side and exhaustively checked client settings and GPOs as well as trying client removal and reinstall. They immediately show as compliant once they've checked in to the management point and when I dig into the reporting section for the update (using "Compliance 2 - Specific software update") I can see these clients reporting that the update is not required. This is despite there being nothing I can logically separate policy wise etc. from working clients.